Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home News

Meduza Stealer Malware Admins Arrested

November 3, 2025
Reading Time: 2 mins read
in News
Microsoft Edge Adds Scareware Sensor

Police in Moscow, in collaboration with the Department for Combating Cybercrime (UBK) and officers from the Astrakhan region, have detained a group of hackers believed to be responsible for the creation and distribution of the notorious Meduza Stealer information-stealing malware. Irina Volk, a police general and official with the Russian Ministry of Internal Affairs, announced the successful operation via Telegram, noting that the perpetrators had been developing and selling the malicious software through hacker forums for approximately two years. This represents a significant law enforcement action against a prominent cybercrime operation.

The Meduza software is a potent infostealer designed to pilfer sensitive data, including account credentials, cryptocurrency wallet information, and other personal data stored within users’ web browsers. The creators operated under a malware-as-a-service (MaaS) business model, providing access to other cybercriminals in exchange for a subscription fee. This accessible distribution method allowed the sophisticated malware to be widely utilized across the dark web market.

Technologically, Meduza was considered one of the more advanced information stealers available. Notably, since December 2023, the malware was capable of “reviving” expired authentication cookies from Chrome, a feature that significantly eased the process of account takeover for its subscribers. Furthermore, a researcher tracking the info-stealer space, ‘g0njxa’, has connected this same group of arrested individuals to the development and distribution of the Aurora Stealer, another prominent malware-as-a-service that gained traction in 2022.

While Russia has historically tolerated domestic cybercriminal activities so long as Russian citizens or organizations were not the targets, this case took a different turn. The authorities initiated a criminal investigation after discovering that some Meduza operators had targeted an institution in Astrakhan, Southern Russia, in May, successfully stealing confidential data from its servers. This local infringement provided the jurisdictional impetus for the arrests.

The three individuals now face criminal charges under Part 2, Article 273 of the Russian Criminal Code, which pertains to the “creation, use, and distribution of malicious computer programs.” The arrests in Moscow underscore a rare instance of Russian law enforcement taking decisive action against a financially successful, internationally recognized hacking group operating within its borders, specifically because their activities ultimately impacted a domestic institution.

Reference:

  • Alleged Meduza Stealer Malware Admins Arrested After Hacking Russian Organization
Tags: Cyber NewsCyber News 2025Cyber threatsNovember 2025
ADVERTISEMENT

Related Posts

Cox Confirms Oracle Hack As Victims Named

Google Adds AirDrop Support To Android

November 24, 2025
Cox Confirms Oracle Hack As Victims Named

Scattered Spider Members Deny TfL Charges

November 24, 2025
Cox Confirms Oracle Hack As Victims Named

Microsoft To Remove WINS After 2025

November 24, 2025
Salesforce Breach Hits Over 200 Victims

Crypto Mixer Founders Jailed for Laundering

November 21, 2025
Salesforce Breach Hits Over 200 Victims

TV Piracy Service With 26M Visits Closed

November 21, 2025
Almaviva Leak Exposes FS Group Data

SEC Ends SolarWinds Case After Years

November 21, 2025

Latest Alerts

Windows 11 24H2 Explorer And Start Crash

Matrix Push C2 Uses Browser Alerts To Phish

ShadowPad Exploits WSUS Flaw For Access

Sturnus Trojan Steals Android Chats

Tsundere Botnet Grows via Game Lures

APT24 Uses BADAUDIO in Taiwan Spying

Subscribe to our newsletter

    Latest Incidents

    Delta Dental Virginia Breach Hits 146000

    Iberia Alerts Customers To Data Breach

    Cox Confirms Oracle Hack As Victims Named

    Over 50000 Asus Routers Compromised

    Salesforce Breach Hits Over 200 Victims

    Almaviva Leak Exposes FS Group Data

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial